Medium severity6.5NVD Advisory· Published Apr 17, 2026· Updated Apr 24, 2026
CVE-2026-28214
CVE-2026-28214
Description
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize() function can overflow the totalLength value when parsing a Wide type clumplet, causing an infinite loop. An authenticated user with INSERT privileges on any table can exploit this via a crafted Batch Parameter Block to cause a denial of service against the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/FirebirdSQL/firebird/security/advisories/GHSA-7cq5-994r-jhrfnvdExploitVendor Advisory
- github.com/FirebirdSQL/firebird/releases/tag/v3.0.14nvdRelease Notes
- github.com/FirebirdSQL/firebird/releases/tag/v4.0.7nvdRelease Notes
- github.com/FirebirdSQL/firebird/releases/tag/v5.0.4nvdRelease Notes
News mentions
0No linked articles in our index yet.